The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Ignore rule creation interface

Prev Next

The Add Ignore Rule option, available in the Attack Log, gives you the flexibility to eliminate alerts that do not actually pose a threat to your network or those that constitute noise. You can achieve this by creating and assigning ignore rules to different attack types in a single interface. Specifically, these are the three objectives that you can accomplish from a single user-interface:

  • Creating and assigning ignore rule objects.

  • Disabling an attack definition from the Default Attack Settings (GARE), Baseline Policy, or Light Weight Policy.

  • Creating and assigning firewall policies.

Consider the three scenarios below that would necessitate the creation and assignment of ignore rules directly from Attack Log:

  • You receive an alert about communication between specific hosts. When you further analyze the alert, you notice that the attack is valid, but not between the specific hosts. In this case, you can create and assign an ignore rule object from Attack Log which ignores the attack taking place between the two hosts for the moment.

  • Many employees in your network are using Yahoo! instant messaging and Facebook chat. You are receiving numerous alerts due to this activity in the network. However, your company's corporate policy does not prevent employees from using such applications. Therefore, you can decide to prevent such alerts from appearing by explicitly disabling the attack definition from Attack Log.

  • A host that is determined safe, such as a vulnerability scanner, in your network is generating noise which you want to ignore. To do this you can create a stateless ACL directly from the Attack Log to ignore all traffic from that host.

Important

This interface will not be available to alerts generated by NTBA.